nerdexam
Citrix

1Y0-231 · Question #105

A Citrix Administrator needs to validate that users are NOT disabling a Microsoft Windows service after connecting to company resources through the Citrix Gateway. What can the administrator…

The correct answer is D. Post-authentication policy. Post-authentication policies are specifically designed to run security checks after a user has already connected, making them the correct tool for validating endpoint conditions (like Windows service states) continuously during an active Citrix Gateway session - they can…

Citrix Gateway

Question

A Citrix Administrator needs to validate that users are NOT disabling a Microsoft Windows service after connecting to company resources through the Citrix Gateway. What can the administrator configure in this scenario?

Options

  • ASmartControl
  • BAppFlow policy
  • CSmartAccess
  • DPost-authentication policy

How the community answered

(24 responses)
  • A
    13% (3)
  • B
    8% (2)
  • C
    4% (1)
  • D
    75% (18)

Explanation

Post-authentication policies are specifically designed to run security checks after a user has already connected, making them the correct tool for validating endpoint conditions (like Windows service states) continuously during an active Citrix Gateway session - they can restrict or terminate sessions if compliance conditions change mid-session.

Why the distractors are wrong:

  • A. SmartControl - Controls ICA proxy behavior and what Citrix Workspace app features users can access; it does not monitor endpoint service states.
  • B. AppFlow policy - Used for traffic analytics and reporting (exports session/flow data to monitoring tools); it observes but does not enforce endpoint compliance.
  • C. SmartAccess - Performs endpoint analysis at login (pre-session), controlling resource access based on endpoint posture at the time of authentication, not during the ongoing session.

Memory tip: Focus on the prefix - Post-authentication = After connecting. The question explicitly says "after connecting," so match the timing: post = after. SmartAccess = before/during login; Post-auth policy = enforcing during/after the session.

Topics

#Post-authentication policy#Citrix Gateway#Endpoint enforcement#Access control

Community Discussion

No community discussion yet for this question.

Full 1Y0-231 Practice